Path traversal in BACnet Field Panels - CVE-2017-9947

 

Path traversal in BACnet Field Panels - CVE-2017-9947

Published: October 13, 2017 / Updated: May 26, 2022


Vulnerability identifier: #VU8820
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9947
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information.

The weakness exists due to path traversal. A remote attacker with network access to the integrated web server (Ports 80/TCP and 443/TCP) can obtain information on the structure of the file system of the affected devices.

Affected software

BACnet Field Panels
TALON TC Modular (BACnet)
TALON TC Compact (BACnet)
APOGEE PXC Modular (BACnet)
APOGEE PXC Compact (BACnet)

How to mitigate CVE-2017-9947

Update to version 3.5.

TALON TC Modular (BACnet) - update to 3.5
TALON TC Compact (BACnet) - update to 3.5
APOGEE PXC Modular (BACnet) - update to 3.5
APOGEE PXC Compact (BACnet) - update to 3.5

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins